-bypass auth using serial number: fortiguard.fortinet.com/psirt/FG-IR-...
-forge cookies to bypass auth: pwner.gg/blog/2025-08...
-bug with exploit in the wild: www.fortiguard.com/psirt/FG-IR-...
And I thought my day was rough yesterday... sheeeeesh!
-bypass auth using serial number: fortiguard.fortinet.com/psirt/FG-IR-...
-forge cookies to bypass auth: pwner.gg/blog/2025-08...
-bug with exploit in the wild: www.fortiguard.com/psirt/FG-IR-...
And I thought my day was rough yesterday... sheeeeesh!
2/
2/
Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices:
fortinet.com/blog/psirt-b...
Data available from 2025-04-11+
shadowserver.org/what-we-do/n...
Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices:
fortinet.com/blog/psirt-b...
Data available from 2025-04-11+
shadowserver.org/what-we-do/n...
psirt.global.sonicwall.com/vuln-detail/...
"SonicWall PSIRT has been notified of possible active exploitation of the referenced vulnerability by threat actors."
psirt.global.sonicwall.com/vuln-detail/...
"SonicWall PSIRT has been notified of possible active exploitation of the referenced vulnerability by threat actors."
https://tech.smarthr.jp/entry/2025/02/26/195338
https://tech.smarthr.jp/entry/2025/02/26/195338
Now I can ask
"Is R1 vulnerable?"
More to come
Now I can ask
"Is R1 vulnerable?"
More to come
267 CERT/PSIRT advisories · 5930 CVEs · 4 added to CISA KEV (actively exploited)
https://www.csirts.com/briefing/2026-09-22
267 CERT/PSIRT advisories · 5930 CVEs · 4 added to CISA KEV (actively exploited)
https://www.csirts.com/briefing/2026-09-22
other vulnerabilities
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.6
other vulnerabilities
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.6
-5-year security roadmaps
-PSIRT teams
-Security policies
Get the full insights in our report: www.linuxfoundation.org/research/cra...
#OpenSource #CRA #EUregulation
-5-year security roadmaps
-PSIRT teams
-Security policies
Get the full insights in our report: www.linuxfoundation.org/research/cra...
#OpenSource #CRA #EUregulation
After 5 1/2 years since being published still over 10K Fortinet firewalls remain unpatched. Actively exploited as recently highlighted by Fortinet: www.fortinet.com/blog/psirt-b...
After 5 1/2 years since being published still over 10K Fortinet firewalls remain unpatched. Actively exploited as recently highlighted by Fortinet: www.fortinet.com/blog/psirt-b...
219 CERT/PSIRT advisories · 3797 CVEs · 1 added to CISA KEV (actively exploited)
https://www.csirts.com/briefing/2026-09-21
219 CERT/PSIRT advisories · 3797 CVEs · 1 added to CISA KEV (actively exploited)
https://www.csirts.com/briefing/2026-09-21
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
1 CERT/PSIRT advisories · 104 CVEs
https://www.csirts.com/briefing/2026-09-20
1 CERT/PSIRT advisories · 104 CVEs
https://www.csirts.com/briefing/2026-09-20
www.fortinet.com/blog/psirt-b...
www.fortinet.com/blog/psirt-b...
CVE-2024-48887, CVSSv3 9.3
fortiguard.fortinet....
#CVE #ThreatIntel
CVE-2024-48887, CVSSv3 9.3
fortiguard.fortinet....
#CVE #ThreatIntel
A patch is here: fortiguard.fortinet.com/psirt/FG-IR-...
A patch is here: fortiguard.fortinet.com/psirt/FG-IR-...
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
URL: fortiguard.fortinet.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
URL: fortiguard.fortinet.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
developers.freee.co.jp/entry/harden...
developers.freee.co.jp/entry/harden...
1 CERT/PSIRT advisories · 129 CVEs
https://www.csirts.com/briefing/2026-09-19
1 CERT/PSIRT advisories · 129 CVEs
https://www.csirts.com/briefing/2026-09-19
The technique allows attackers to maintain read-only access to FortiGate devices they previously infected. (1/2)
www.fortinet.com/blog/psirt-b...
The technique allows attackers to maintain read-only access to FortiGate devices they previously infected. (1/2)
www.fortinet.com/blog/psirt-b...